pkgconf version 1.5.0 to 1.5.2 contains a Buffer Overflow vulnerability in dequote() that can result in dequote() function returns 1-byte allocation if initial length is 0, leading to buffer overflow. This attack appear to be exploitable via specially crafted .pc file. This vulnerability appears to have been fixed in 1.5.3.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-17T00:05:27.313Z

Reserved: 2018-08-20T00:00:00Z

Link: CVE-2018-1000221

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-20T20:29:01.190

Modified: 2024-11-21T03:39:57.867

Link: CVE-2018-1000221

cve-icon Redhat

Severity : Low

Publid Date: 2018-08-24T00:00:00Z

Links: CVE-2018-1000221 - Bugzilla